Proving identity and protecting credentials in a work-from-anywhere world
August 7, 2026 | 9 minute read
Key takeaways
- Remote work has expanded the number of vulnerable entry points threat actors can use to breach corporate networks.
- “Trust but verify” must be reinforced with integrated security architectures that protect both networks and remote teams.
- Best practices for access security include single sign-on, multifactor authentication, least-privileged access and zero-trust principles.
- Extend secure access practices beyond on-premises systems to cloud-based systems and data.
Remote and hybrid work has expanded organizations’ attack surfaces, creating more entry points for cybercriminals to exploit. Threat actors can take advantage of potentially unsecured personal devices and public or home Wi Fi. At the same time, keeping remote workers trained on evolving work from anywhere security practices remains a challenge. As cybercriminals adapt to these conditions, the result is a sharp increase in breaches involving stolen employee credentials. Security incidents stemming from compromised credentials cost companies an average of $4.67 million,1 underscoring the need for organizations to closely evaluate how credentials and access are managed across a distributed workforce.
Conventional “trust but verify” models fall short against modern cyberthreats. Traditional on-premises corporate security operates on the assumption that anyone inside the building is trustworthy. This model, while convenient, creates significant risk if credentials are compromised. For cybercriminals, once they have an employee’s credentials, they can access data across the network, including sensitive financial or proprietary information.
“For cybercriminals, once they have an employee’s credentials, they can access data across the network, including sensitive financial or proprietary information.”
Cybercriminals use various methods to target credentials, including illicitly installed malware that logs keystrokes. Many recent high-profile breaches have involved the use of previously stolen credentials from past breaches that were sold in underground criminal markets. Reusing passwords or failing to update them regularly makes it easier for attackers to exploit credentials exposed in past breaches.
Use these credential and access-management best practices to help keep your network secure.
Focus on password hygiene
Credential theft remains one of the most frequent causes of data breaches. In 2025, 22% of analyzed breaches involved compromised credentials.2
Criminals can purchase large datasets of verified credentials stolen from past breaches — known as “credential stuffing” — to gain access to accounts and services. To reduce this risk, organizations should prevent password reuse, enforce regular updates and require longer passwords. The Cybersecurity and Infrastructure Security Agency (CISA) recommends passwords of at least 16 characters, with longer passphrases providing stronger protection.3
Implement multifactor authentication
Multifactor authentication (MFA) strengthens access controls by requiring users to verify their identity using two or more factors: something they know (like a password or passphrase), something they have (like a one‑time code sent to a mobile device) or something they are (like biometric identifiers). By combining these factors, MFA helps ensure that only authorized individuals gain access, even if usernames and passwords are compromised.
Embrace single sign-on
When users are prompted to change too many passwords or change passwords too frequently, this can lead to password fatigue, resulting in slightly altered existing passwords. Single sign-on, or SSO, helps mitigate password fatigue by streamlining access across systems.
Use push notifications to verify access
One of the simplest and most effective ways to verify a user’s identity during login is through push authentication. When a login attempt occurs, a notification is sent to the mobile device linked to the user’s account, allowing the user to approve or deny the request. Access is granted only after confirmation, adding a real‑time layer of protection.
Employ least-privileged access
Least-privileged access limits each user to only the systems and data required for their role, reducing the potential impact of a breach if credentials are compromised.
Move toward zero trust
The evolving threat landscape highlights the importance of adopting a zero‑trust security model, which operates on the principle of “never trust, always verify.” Under a zero‑trust approach, users and devices are not trusted by default, and access is granted on a limited, context‑specific basis — only to the resources required and only for as long as necessary.
Secure your cloud
Many organizations secure on-premises systems but apply less rigor in the cloud. To prevent accidental exposure or unauthorized access, it’s essential to extend identity and access controls to cloud‑based resources and encrypt data both in transit and at rest using encryption keys that you manage. Since cloud providers are not responsible for securing your data, applying these controls consistently helps protect information across environments and supports regulatory compliance.
1 IBM and Ponemon Institute, “Cost of a Data Breach Report 2025,” July 2025.
2 Verizon, “2025 Data Breach Investigations Report,” April 2025.
3 CISA, “Require Strong Passwords”
How to protect your card program from fraud
Increased Chip and PIN adoption for corporate cards has made it harder for fraudsters to create and use counterfeits, leading them to embrace aggressive new tactics to compromise card programs.
Security & Information Management
Phishing. Vishing. Smishing. Keeping up with threats from scams, fraud and cyberattacks is difficult. Our resources and insights can help you protect your company and customers.
Important Disclosures and Information
Bank of America, Merrill, their affiliates and advisors do not provide legal, tax or accounting advice. Consult your own legal and/or tax advisors before making any financial decisions. Any informational materials provided are for your discussion or review purposes only. The content on the Center for Business Empowerment (including, without limitations, third party and any Bank of America content) is provided “as is” and carries no express or implied warranties, or promise or guaranty of success. Bank of America does not warrant or guarantee the accuracy, reliability, completeness, usefulness, non-infringement of intellectual property rights, or quality of any content, regardless of who originates that content, and disclaims the same to the extent allowable by law. All third party trademarks, service marks, trade names and logos referenced in this material are the property of their respective owners. Bank of America does not deliver and is not responsible for the products, services or performance of any third party.
Not all materials on the Center for Business Empowerment will be available in Spanish.
Certain links may direct you away from Bank of America to unaffiliated sites. Bank of America has not been involved in the preparation of the content supplied at unaffiliated sites and does not guarantee or assume any responsibility for their content. When you visit these sites, you are agreeing to all of their terms of use, including their privacy and security policies.
Credit cards, credit lines and loans are subject to credit approval and creditworthiness. Some restrictions may apply.
Merrill Lynch, Pierce, Fenner & Smith Incorporated (also referred to as “MLPF&S” or “Merrill”) makes available certain investment products sponsored, managed, distributed or provided by companies that are affiliates of Bank of America Corporation (“BofA Corp.”). MLPF&S is a registered broker-dealer, registered investment adviser, Member SIPC, and a wholly owned subsidiary of BofA Corp.
Banking products are provided by Bank of America, N.A., and affiliated banks, Members FDIC, and wholly owned subsidiaries of BofA Corp.
“Bank of America” and “BofA Securities” are the marketing names used by the Global Banking and Global Markets division of Bank of America Corporation. Lending, derivatives, other commercial banking activities, and trading in certain financial instruments are performed globally by banking affiliates of Bank of America Corporation, including Bank of America, N.A., Member FDIC. Trading in securities and financial instruments, and strategic advisory, and other investment banking activities, are performed globally by investment banking affiliates of Bank of America Corporation (“Investment Banking Affiliates”), including, in the United States, BofA Securities, Inc., which is a registered broker-dealer and Member of SIPC, and, in other jurisdictions, by locally registered entities. BofA Securities, Inc. is a registered futures commission merchant with the CFTC and a member of the NFA.
Investment products: